2026 CVE Vulnerabilities

69,544 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31800CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30972HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-al...
CVE-2026-30967HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30966CRITICAL10Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30965CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30962MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30954MEDIUM4.3LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRep...
CVE-2026-30953MEDIUM6.5LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetche...
CVE-2026-30952HIGH7.5liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render...
CVE-2026-30951HIGH7.5Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where cla...
CVE-2026-30949HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30948MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30947HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30946HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alph...
CVE-2026-30837HIGH7.5Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi...
CVE-2026-0124HIGH7.8There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ...
CVE-2026-0123HIGH8.4In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds...
CVE-2026-0122HIGH8.4In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code exe...
CVE-2026-0121LOW2.9In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure...
CVE-2026-0120CRITICAL9.8In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execu...
CVE-2026-0119MEDIUM6.8In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This ...
CVE-2026-0118HIGH8.4In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalati...
CVE-2026-0117HIGH8.4In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could...
CVE-2026-0116CRITICAL9.8In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2026-0115LOW2.1In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could le...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now